Show filters
51 Total Results
Displaying 21-30 of 51
Sort by:
Attacker Value
Unknown

CVE-2023-3869

Disclosure Date: October 20, 2023 (last updated October 27, 2023)
The wpDiscuz plugin for WordPress is vulnerable to unauthorized modification of data due to a missing authorization check on the voteOnComment function in versions up to, and including, 7.6.3. This makes it possible for unauthenticated attackers to increase or decrease the rating of a comment.
Attacker Value
Unknown

CVE-2023-2309

Disclosure Date: July 24, 2023 (last updated October 08, 2023)
The wpForo Forum WordPress plugin before 2.1.9 does not escape some request parameters while in debug mode, leading to a Reflected Cross-Site Scripting vulnerability.
Attacker Value
Unknown

CVE-2023-33213

Disclosure Date: June 19, 2023 (last updated October 08, 2023)
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in gVectors Display Custom Fields – wpView plugin <= 1.3.0 versions.
Attacker Value
Unknown

CVE-2023-2249

Disclosure Date: June 09, 2023 (last updated October 08, 2023)
The wpForo Forum plugin for WordPress is vulnerable to Local File Include, Server-Side Request Forgery, and PHAR Deserialization in versions up to, and including, 2.1.7. This is due to the insecure use of file_get_contents without appropriate verification of the data being supplied to the function. This makes it possible for authenticated attackers, with minimal permissions such as a subscriber, to retrieve the contents of files like wp-config.php hosted on the system, perform a deserialization attack and possibly achieve remote code execution, and make requests to internal services.
Attacker Value
Unknown

CVE-2023-33216

Disclosure Date: May 28, 2023 (last updated October 08, 2023)
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in gVectors Team WooDiscuz – WooCommerce Comments woodiscuz-woocommerce-comments allows Stored XSS.This issue affects WooDiscuz – WooCommerce Comments: from n/a through 2.2.9.
Attacker Value
Unknown

CVE-2022-4641

Disclosure Date: December 21, 2022 (last updated October 08, 2023)
A vulnerability was found in pig-vector and classified as problematic. Affected by this issue is the function LogisticRegression of the file src/main/java/org/apache/mahout/pig/LogisticRegression.java. The manipulation leads to insecure temporary file. The attack needs to be approached locally. The name of the patch is 1e7bd9fab5401a2df18d2eabd802adcf0dcf1f15. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-216500.
Attacker Value
Unknown

CVE-2022-40206

Disclosure Date: November 26, 2022 (last updated December 22, 2024)
Insecure direct object references (IDOR) vulnerability in the wpForo Forum plugin <= 2.0.5 on WordPress allows attackers with subscriber or higher user roles to mark any forum post as private/public.
Attacker Value
Unknown

CVE-2022-40192

Disclosure Date: November 17, 2022 (last updated December 22, 2024)
Cross-Site Request Forgery (CSRF) vulnerability in wpForo Forum plugin <= 2.0.9 on WordPress.
Attacker Value
Unknown

CVE-2022-40200

Disclosure Date: November 09, 2022 (last updated December 22, 2024)
Auth. (subscriber+) Arbitrary File Upload vulnerability in wpForo Forum plugin <= 2.0.9 on WordPress.
Attacker Value
Unknown

CVE-2022-43492

Disclosure Date: October 28, 2022 (last updated December 22, 2024)
Auth. (subscriber+) Insecure Direct Object References (IDOR) vulnerability in Comments – wpDiscuz plugin 7.4.2 on WordPress.